Anthropic Mythos AI Bug Hunter Turns Into Attack Weapon
Anthropic's Mythos vulnerability model found a critical flaw in Rejetto HFS—and a Chinese threat actor exploited it within 24 hours. The line between AI-assisted defense and offense is collapsing faster than anyone anticipated.
The Exploit Chain Moved Faster Than the Patch
Anthropic has spent months selling Mythos as the end of bad code. The model—accessible only through Project Glasswing, Anthropic’s gated partner program—has found 286 CVEs since April. That’s a striking number for any vulnerability discovery engine, secure or not. But the real story isn’t how good Mythos is at finding flaws. It’s how fast those flaws become weaponized once the methodology leaks.
CVE-2026-61500 was discovered by Zach Hanley at AI pen-testing firm Horizon3 on Wednesday. Hanley used Mythos to identify a critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS), a Node.js-based file sharing tool that the US Cybersecurity and Infrastructure Security Agency had already flagged as dangerously understudied. By Thursday evening, Patrick Garrity at VulnCheck was posting on LinkedIn that exploitation activity had begun—originating from a single IP in China, targeting hosts in the US and Japan.
Twenty-four hours. That’s the gap now between a vulnerability discovery announcement and active exploitation in the wild. And it’s not because the bug was trivially easy to find. Hanley himself wrote that his team could not recall ever seeing an SMT (Satisfiability Modulo Theories) solver deployed this way—to reverse-engineer a PRNG and chain it with an information leak to forge session cookies and bypass authentication. This was not a copy-paste exploit. It was a novel attack chain built on cryptographic reasoning.
How Mythos Actually Found This
The vulnerability sits in how HFS handles authentication. The application calls V8’s Math.random() to generate a session value, passes it to Koa, which uses keygrip to sign cookies. On paper, this assumes Math.random() behaves like a secure pseudo-random number generator. In practice, V8 implements it using xorshift128+, a PRNG that is publicly documented, fully reversible, and catastrophically unsuitable for cryptographic use.
Here’s where Mythos did something most human researchers would struggle to reproduce in a single session. The model didn’t just flag that Math.random() was insecure. It simultaneously identified two separate facts: first, that the PRNG output was predictable; second, that HFS was leaking raw Math.random() values through a different code path. Crucially, it recognized these two facts as a chain. The leak provided exactly the observations needed to recover the PRNG seed using Z3, a Microsoft-developed SMT solver.
Hanley noted this was distinctive. Finding an insecure PRNG is a common static analysis result. Finding an SMT-solver-based state recovery attack that chains multiple code paths into a remote code execution vector is something else entirely. It required the model to hold a cryptographic attack strategy, map it onto the application’s actual execution paths, and verify that the constraints were solvable—all in one pass.
The Real Cost Isn’t the Vulnerability. It’s the Methodology.
The immediate damage from CVE-2026-61500 is bounded. Rejetto HFS is niche software. The fix—updating to version 3.2.1 or later—exists. Four hits have been recorded so far, spanning two US proxy IPs in the same subnet, likely compromised devices used to mask the attacker’s origin. This is consistent with a pattern a ten-country security advisory flagged in April: China-nexus operatives using proxy networks strategically and at scale to disguise attribution.
But the methodology is unbounded. And that’s what changes the landscape.
Before Mythos, turning a theoretical cryptographic weakness into a working exploit against a real application required deep expertise in symbolic execution, SMT solving, and application-level code tracing. You needed researchers who understood both the math and the machinery. You needed time.
Mythos compressed that entire workflow into a single API call. The exploit video Hanley published showed the steps clearly enough that any actor with basic reverse-engineering skills could follow along. By Thursday night, someone did. Not a nation-state APT with months of preparation. A single threat actor operating from a Chinese IP, using compromised US proxies, hitting targets across two countries. The barrier to entry just dropped for everyone.
Who Wins and Who Loses
Horizon3 wins on credibility. Joining Project Glasswing in July has given them a discovery pipeline that outpaces traditional security research teams. Twenty-eight CVEs attributed to Mythos and Glasswing since April is not marketing copy—it’s a competitive moat built on access to a model Anthropic refuses to release publicly. Hanley’s own assessment was measured: “many critical vulnerabilities” discovered, a capability that now has a documented proof of concept in the public record.
Anthropic wins too, but conditionally. They’ve demonstrated that their most powerful models can perform at a level that redefines what vulnerability research looks like. The catch is that their containment strategy is failing. Mythos is not general-public-accessible by design, but the outputs are. Every CVE report, every blog post, every exploitation video becomes training data for the next actor who wants to do the same thing without the API key.
Rejetto HFS users lose today. The patch exists, but the window between discovery and active exploitation is shrinking toward zero. CISA already had this software on its Known Exploited Vulnerabilities catalog in 2024. The new flaw doesn’t make HFS worse—it makes the entire category of AI-discovered vulnerabilities more dangerous.
The Chinese threat actor wins in the narrowest sense. Four hits against US and Japanese servers from a single operational IP is a low-impact intrusion campaign. But the actor proved that an AI-generated vulnerability chain can be turned into live exploitation faster than vendors can patch. That’s the model going forward.
What Happens Next
The timeline is the story. April: Project Glasswing launches. By July, Horizon3 is inside and reporting critical findings. By October, the first Mythos-discovered CVE has moved from discovery to active exploitation in under a day. Twenty-eight vulnerabilities discovered, one previously exploited before Wednesday. That pattern is accelerating, not stabilizing.
Other security firms will join Glasswing or build their own AI-assisted research pipelines. The models will get better at the kind of multi-step cryptographic reasoning this exploit required. And the gap between finding a vulnerability and weaponizing it will continue to collapse.
Anthropic’s position—that Mythos is too powerful to release widely—is technically defensible but operationally hollow. The outputs are already public. The methodologies are already documented. The constraint that kept this capability contained wasn’t access to the model itself. It was access to human expertise capable of translating model findings into working exploits. That constraint is disappearing.
The fix for Rejetto HFS is straightforward. Update to 3.2.1. The fix for the broader problem doesn’t exist yet. There is no patch for the fact that AI can now turn a cryptographic observation into a remote code execution chain faster than the security industry can respond.